ATT&CKSoftwareIPsec Helper

IPsec Helper

S1132

Malware.View on attack.mitre.org

About this malware

IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

IPsec Helper can identify specific files and folders for follow-on exfiltration.

T1027.013
Encrypted/Encoded File

IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution.

T1041
Exfiltration Over C2 Channel

IPsec Helper exfiltrates specific files through its command and control framework.

T1057
Process Discovery

IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node.

T1059.001
PowerShell

IPsec Helper can run arbitrary PowerShell commands passed to it.

T1059.003
Windows Command Shell

IPsec Helper can run arbitrary commands passed to it through cmd.exe.

T1059.005
Visual Basic

IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it.

T1070
Indicator Removal

IPsec Helper can delete various registry keys related to its execution and use.

T1070.004
File Deletion

IPsec Helper can delete itself when given the appropriate command.

T1070.009
Clear Persistence

IPsec Helper can delete various service traces related to persistent execution when commanded.

T1071.001
Web Protocols

IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware.

T1112
Modify Registry

IPsec Helper can make arbitrary changes to registry keys based on provided input.

T1497.003
Time Based Checks

IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow.

T1569.002
Service Execution

IPsec Helper is run as a Windows service in victim environments.

T1570
Lateral Tool Transfer

IPsec Helper can download additional payloads from command and control nodes and execute them.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SentinelOne Agrius 2021 Open source
    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.